Fortinet FortiGate SSO Zero-Day Actively Exploited to Create Rogue Admin Accounts

Listen to this Post

Featured Image

A Silent Takeover Threat Facing Internet-Exposed Firewalls

A newly uncovered security vulnerability in Fortinet’s FortiGate firewalls has escalated into an active exploitation campaign, giving attackers the ability to silently create unauthorized administrator accounts. The flaw targets Fortinet’s Single Sign-On (SSO) mechanism and allows full device compromise without valid credentials. As reports continue to surface from multiple organizations worldwide, the incident is rapidly becoming one of the most serious FortiGate security threats observed in late 2025 and early 2026.

The vulnerability, tracked as CVE-2025-59718, affects FortiGate devices using FortiCloud SSO or SAML authentication for administrative access and exposed directly to the internet. Despite Fortinet releasing guidance and preparing patches, real-world exploitation remains ongoing, placing thousands of enterprise firewalls at immediate risk.

Active Exploitation Confirmed Across Multiple Organizations

Security teams from different regions have independently reported identical attack patterns, indicating a coordinated and systematic campaign rather than isolated incidents. In each confirmed case, attackers successfully bypassed authentication controls and created new local administrator accounts with full privileges.

Fortinet’s Product Security Incident Response Team (PSIRT) has acknowledged the issue and launched a forensic investigation to assess the scope and techniques used in these attacks. The persistence of exploitation, even after partial mitigation guidance, has intensified concerns across the cybersecurity community.

How CVE-2025-59718 Works

CVE-2025-59718 exploits a flaw in the FortiCloud SSO login mechanism within FortiOS. By sending specially crafted SSO login requests, a remote attacker can bypass authentication checks entirely. Once access is gained, the attacker escalates privileges and creates a local administrator account directly on the firewall.

In most observed cases, the backdoor account is named “helpdesk”, though security experts warn that attackers could easily change naming conventions to evade detection. These accounts grant full administrative control, allowing configuration changes, traffic interception, policy manipulation, and long-term persistence.

Devices and Configurations at Risk

The vulnerability primarily impacts FortiGate firewalls that meet the following conditions:

FortiCloud SSO or SAML authentication enabled for administrative access

Device exposed to the internet

Running vulnerable FortiOS versions

Notably, local authentication and standard SAML configurations remain unaffected when FortiCloud SSO is disabled, making targeted mitigation possible without breaking all administrative access.

Community Discovery and Real-World Evidence

Initial reports surfaced on Reddit, where security professionals described unexplained administrator account creation on FortiGate devices running FortiOS 7.4.9, including widely deployed FGT60F models. In several incidents, a single malicious SSO login attempt from a specific IP address was enough to trigger the exploit.

One security team noted that their Local-In firewall policies failed because the device was fully internet-accessible. Another organization using SAML authentication confirmed the sudden appearance of the “helpdesk” account despite no internal administrative changes.

These attacks began appearing in late December 2025, ruling out older firmware vulnerabilities and confirming this as a current and active threat.

Patch Status and Exposure Scale

Fortinet developers have confirmed that the vulnerability remains unpatched in FortiOS 7.4.10, with fixes planned for upcoming releases. The Shadowserver Foundation further amplified concerns after reporting that more than 25,000 Fortinet devices were publicly accessible with FortiCloud SSO enabled as of mid-December 2025.

FortiOS Version Vulnerability Status Fix Availability

7.4.9 Vulnerable (actively exploited) 7.4.11 (scheduled)

7.4.10 Vulnerable (unpatched) 7.4.11 (scheduled)

7.6.x Vulnerable 7.6.6 (scheduled)

8.0.x Vulnerable (pre-release) 8.0.0 (scheduled)

Earlier versions may also be affected, and organizations are advised to monitor Fortinet’s official advisories for complete coverage details.

Emergency Mitigation Recommended by Fortinet

To immediately block exploitation attempts, Fortinet has issued a critical workaround that disables FortiCloud SSO logins without affecting local or SAML authentication.

Administrators should execute the following CLI commands:

pgsql

Copy code

config system global

set admin-forticloud-sso-login disable

end

This mitigation should remain in place until official patches are applied and validated.

Immediate Defensive Actions for Organizations

Security teams are urged to act without delay by implementing the following measures:

Audit Logs: Search for suspicious SSO login attempts and unauthorized admin accounts, especially “helpdesk”

Network Segmentation: Restrict administrative access using strict Local-In firewall rules

SIEM Monitoring: Trigger alerts for admin account creation and correlate events by source IP

Patch Planning: Prepare upgrades to fixed FortiOS versions once released

Incident Response: Rotate credentials, isolate affected devices, and engage Fortinet support if compromise is suspected

What Undercode Say:

A Dangerous Pattern in SSO Security Design

This Fortinet incident reinforces a recurring problem in enterprise security appliances: SSO features expanding attack surfaces faster than defensive controls evolve. While SSO improves usability and centralized access management, it also introduces complex trust relationships that attackers increasingly exploit.

Internet-Exposed Management Interfaces Remain a Critical Risk

The consistent factor across all reported cases is direct internet exposure. Administrative interfaces, regardless of vendor reputation, remain high-value targets. This campaign highlights how a single misconfiguration combined with a zero-day flaw can grant attackers full control within seconds.

Backdoor Account Creation Signals Long-Term Intent

The creation of persistent administrator accounts suggests that attackers are not merely scanning or testing exploits. Instead, this behavior aligns with long-term access objectives, potentially enabling espionage, lateral movement, or future ransomware deployment.

Patch Delays Amplify Real-World Damage

The confirmed lack of fixes in multiple FortiOS versions underscores a dangerous window between vulnerability disclosure and patch availability. During this gap, attackers move faster than defenders, especially when exploit reliability is high.

SSO Should Never Be “Set and Forget”

Organizations often deploy SSO once and assume it is inherently secure. This incident proves that continuous monitoring, feature minimization, and strict access controls must accompany any SSO implementation—especially on perimeter devices.

This Is Not Just a Fortinet Problem

While Fortinet is the vendor in focus, the broader lesson applies across the industry. Any firewall, VPN, or network appliance offering cloud-based authentication is a potential entry point if not tightly controlled and continuously audited.

Fact Checker Results

Verified Exploitation Activity

✅ Multiple independent organizations confirmed real-world exploitation patterns.

Patch Status Confirmed

❌ Several affected FortiOS versions remain unpatched at the time of reporting.

Scope of Exposure

✅ Shadowserver data supports the claim of tens of thousands of exposed devices.

Prediction

Increased Targeting of Network Appliances

🔮 Attackers will continue prioritizing firewalls and VPNs due to their privileged network position.

Surge in SSO-Focused Vulnerabilities

🔮 More zero-day flaws will emerge in SSO and cloud-auth integrations across vendors.

Regulatory and Vendor Pressure Ahead

🔮 Incidents like this will accelerate demands for faster patch cycles and stricter default security settings.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon